cNotes 検索 一覧 カテゴリ

Facebookからのメッセージを騙るスパム

Published: 2013/02/02

Facebookネタは相変わらず人気です。

新しいコメントがとどいたとか、パスワードを変えろとか。

誘導URLはこんな感じ。

 http://www.cross-capital.cc/fb_recoverr.html
 http://calendar.aretesw.com/fb_recoverr.html
 http://higginsteam.voitco.com/fb_recoverr.html
 http://ultimatebabyguide.com/recovr_fbcom.html
 http://www.dobrekomputery.ovh.org/recovr_fbcom.html

この後

 http://capeinn.net/detects/win_units.php 

に飛ばされます。

はやりのBHEK2ではなくコードはZeuSっぽいです。


domainIP逆引きASAS NameCountry
bjwmng.com122.115.36.190NONE4808CHINA169-BJ_CNCGROUP_IP_network_China169_Beijing_Province_NetworkChina
www.eliteedu.com.cn122.115.36.190NONE4808CHINA169-BJ_CNCGROUP_IP_network_China169_Beijing_Province_NetworkChina
www.xorencom.lu195.46.239.232NONE6661EPT-LU_Entreprise_des_Postes_et_TelecommunicationsLuxembourg
test.login-users.eu81.169.145.154w9a.rzone.de.6724STRATO_STRATO_AGGermany
ant.graine.ru81.177.140.211NONE8342RTCOMM-AS_OJSC_RTComm.RURussianFederation
tv.graine.ru81.177.140.211NONE8342RTCOMM-AS_OJSC_RTComm.RURussianFederation
www.peredki.borovichskiy.okpmo.nov.ru62.118.131.170NONE8359MTS_MTS_OJSCRussianFederation
piccollini.dk212.97.132.115ws15.surf-town.net.9120SURFTOWNNET_Surftown_A/SDenmark
www.dobrekomputery.ovh.org46.105.198.1NONE16276OVH_OVH_SystemsFrance
www.imteeaz.com178.33.232.2fr3.fodytechnologies.com.16276OVH_OVH_SystemsFrance
nunu.ictpurwakarta.net180.250.69.6060.subnet180-250-69.speedy.telkom.net.id.17974TELKOMNET-AS2-AP_PT_Telekomunikasi_IndonesiaIndonesia
shop.majevent.com85.249.230.97mailtalin.beget.ru.20597ELTEL-AS_ELTEL.NET_Autonomous_SystemRussianFederation
forum.network-biznes.com.ua77.120.115.235accord.cityhost.com.ua.25229VOLIA-AS_Kyivski_Telekomunikatsiyni_Merezhi_LLCUkraine
old.mlsit.ru90.156.201.112fe.shared.masterhost.ru.25532MASTERHOST-AS_.masterhost_autonomous_systemRussianFederation
old.mlsit.ru90.156.201.117fe.shared.masterhost.ru.25532MASTERHOST-AS_.masterhost_autonomous_systemRussianFederation
old.mlsit.ru90.156.201.25fe.shared.masterhost.ru.25532MASTERHOST-AS_.masterhost_autonomous_systemRussianFederation
old.mlsit.ru90.156.201.51fe.shared.masterhost.ru.25532MASTERHOST-AS_.masterhost_autonomous_systemRussianFederation
mackidockie.co.uk66.96.160.129129.160.96.66.static.eigbox.net.29873BIZLAND-SD_-_The_Endurance_International_Group_Inc.UnitedStates
barmanbeck.voitco.com205.186.187.246ekiaiomcqk.c06.mtsvc.net.31815MEDIATEMPLE_-_Media_Temple_Inc.UnitedStates
fultsmcloughlin.voitco.com205.186.187.246ekiaiomcqk.c06.mtsvc.net.31815MEDIATEMPLE_-_Media_Temple_Inc.UnitedStates
higginsteam.voitco.com205.186.187.246ekiaiomcqk.c06.mtsvc.net.31815MEDIATEMPLE_-_Media_Temple_Inc.UnitedStates
s30420.gridserver.com64.13.232.190acmkoieemk.gs02.gridserver.com.31815MEDIATEMPLE_-_Media_Temple_Inc.UnitedStates
africansinitiative.zeyzone.com96.0.170.1rev.opentransfer.com.1.170.0.96.in-addr.arpa.32392OPENTRANSFER-ECOMMERCE_-_Ecommerce_CorporationUnitedStates
store.zeyzone.com96.0.170.1rev.opentransfer.com.1.170.0.96.in-addr.arpa.32392OPENTRANSFER-ECOMMERCE_-_Ecommerce_CorporationUnitedStates
banknotes.notapedia.com198.23.48.120hosted.by.liquidnetlimited.com.32748STEADFAST_-_Steadfast_NetworksUnitedStates
eurotilingsys.com198.23.48.142hosted.by.liquidnetlimited.com.32748STEADFAST_-_Steadfast_NetworksUnitedStates
globalsourcingandimports.com198.23.48.104hosted.by.liquidnetlimited.com.32748STEADFAST_-_Steadfast_NetworksUnitedStates
itouregypt.com198.23.48.142hosted.by.liquidnetlimited.com.32748STEADFAST_-_Steadfast_NetworksUnitedStates
photos.twicmayardit.com208.117.45.29NONE32748STEADFAST_-_Steadfast_NetworksUnitedStates
ultimatebabyguide.com198.136.54.115direct.host-care.com.33182DIMENOC_-_HostDime.com_Inc.UnitedStates
calendar.aretesw.com208.72.23.197NONE33219UMCC-2_-_Ultimate_Medium_Communications_Corp.UnitedStates
www.cross-capital.cc85.158.181.24server451-han.de-nserver.de.34432PHH-AS_Profihost_AGGermany
doradcy.infonetax.pl83.143.132.2132-2.dmtec.eu.35174NFB-AS_Network_For_Business_Sp._z_o.o.Poland
dump.woano.lv85.31.96.3685.31.96.36.static.nano.lv.43513NANO-AS_Sia_Nano_ITLatvia
www.shiatsubackmassager.co.uk142.4.0.62142-4-0-62.unifiedlayer.com.46606UNIFIEDLAYER-AS-1_-_Unified_LayerUnitedStates
test.carecase.nl94.228.209.9NONE47869NETROUTING-AS_Netrouting_Data_FacilitiesNetherlands
findoks.pl91.228.197.8484.eight.greendata.pl.198414BIZNESHOST-AS_Biznes-Host.pl_sp._z_o.o.Poland

攻撃サイトは韓国にあります。

 capeinn.net has address 222.238.109.66
 
 [ Network Information ]
 IPv4 Address       : 222.232.0.0 - 222.239.255.255 (/13)
 Service Name       : broadNnet
 Organization Name  : SK Broadband Co Ltd
 Organization ID    : ORG3930
 
 [ Network Information ]
 IPv4 Address       : 222.238.64.0 - 222.238.127.255 (/18)
 Network Name       : HANANET-INFRA
 Organization Name  : SK Broadband Co Ltd
 Organization ID    : ORG3930

[カテゴリ:spam観察日記]

by jyake